Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
104
Detects the creation of PHP files within the 'wp-content/uploads/elementor/forms/' directory of a WordPress installation. This behavior is highly suspicious as it often indicates an attempt by an attacker to deploy a web shell or other malicious script following successful exploitation of the Elementor plugin, which allows for arbitrary file uploads.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
104
This rule detects modifications to Windows Registry persistence keys (Run and RunOnce) associated with specific suspicious filenames ('cplsupport.exe', 'wtass.exe'), as well as modifications to specific Synapse agent configuration registry keys. These patterns are often associated with persistence mechanisms or unauthorized software configuration changes.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
004
This rule monitors for two distinct indicators of compromise: it detects the execution of files dropped into specific patterns within the 'AppData\Roaming' directory (associated with potential GoCaracal malware) and identifies network connections to known C2 infrastructure associated with GoCaracal and Bandook malware families.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
11012
Detects the creation of PHP files within the 'wp-content/uploads/elementor/forms/' directory of a WordPress installation. This behavior is highly suspicious as it often indicates an attempt by an attacker to deploy a web shell or other malicious script following successful exploitation of the Elementor plugin, which allows for arbitrary file uploads.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
104
Detects usage of the 'finger' utility via command line within scripts or batch files, or network connections originating from the 'finger' process on port 79 to non-internal destinations. This activity is commonly associated with internal network reconnaissance to gather user information or system details.
avatar
Ankit Mehta@Secvyn
Defender - KQL
27 days ago
000
Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
27 days ago
000
Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
avatar
Ankit Mehta@Secvyn
Defender - KQL
27 days ago
000
Detects usage of the 'finger' utility via command line within scripts or batch files, or network connections originating from the 'finger' process on port 79 to non-internal destinations. This activity is commonly associated with internal network reconnaissance to gather user information or system details.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects command-line execution patterns consistent with the SloppyRAT stager, specifically using IronPython to execute base64-encoded and zlib-compressed payloads from suspicious directories like AppData or Local. The rule looks for the simultaneous presence of encoding/compression indicators and execution primitives (subprocess or Popen).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects instances where PowerShell is launched with explorer.exe as its parent process, but where the child process's metadata (creation time, logon ID, or account SID) does not align with the recorded explorer.exe process. This discrepancy is a strong indicator of Parent Process ID (PPID) spoofing, a technique often used to evade security monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
000
Detects the presence of Chrome Remote Desktop processes or execution of Windows Installer (msiexec.exe) and GoogleUpdate.exe, which are often used by adversaries for remote access or as a proxy for malicious payload execution.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
8014
DNSExfiltrator allows for transferring (exfiltrate) a file over a DNS request covert channel
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
205
Adversaries may carry out malicious operations using a virtual instance to avoid detection
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
105
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Page 406 of 1870